CVE-2024-23222 is a critical type confusion vulnerability impacting multiple Apple products, including iOS, iPadOS, macOS, Safari, tvOS, and visionOS. This high-severity flaw (CVSS 8.8) allows arbitrary code execution when processing maliciously crafted web content, requiring user interaction but having low attack complexity. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog and association with the "Coruna" exploit. Apple has released patches across various operating system versions, including backports for older devices, to address this significant threat. While no public exploit code is widely available, the active exploitation and extensive media coverage highlight its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 15.8.7CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.7.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.3CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.8.7CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.